OnlyState: Zero-Knowledge Prime Integer Relations
Social consensus, distilled to a single integer
OnlyState: Zero-Knowledge Prime Integer Relations
The Problem
On-chain identity and membership systems suffer from state bloat. Every member is a wallet address stored on-chain. As groups grow, gas costs explode. A DAO with 100,000 members requires storing 100,000 addresses — and every membership change requires a transaction.
OnlyState eliminates this entirely.
O(1) State Formula
An entire social group of 100,000 members is represented on-chain as exactly one 16-element array — the group's Thue-Morse sequence. The Prouhet-Tarry-Escott power-sum equations verified by the ZK circuit ensure membership without storing a single wallet address.
No databases. No identity arrays. No state bloat. Just pure Proof-of-Coherence.
Architecture
Client Layer (Browser / WASM)
Users enter a private vector. snarkjs runs the ZK circuit locally, generating a Groth16 proof (pA, pB, pC) — 300–500 bytes — and submits it to chain.
On-Chain Layer (Solidity)
- OnlyState.sol — createGroup(), proveCoherenceAndJoin(), verifyMembership()
- OSTA.sol — ERC-20 token minted exclusively by solving the ZK-PIR circuit
- Verifier.sol — auto-generated by snarkjs, verifies Groth16 proofs on-chain
Off-Chain Coherence Nodes (Rust)
Axum + tokio + redb (persistent KV) + moka (in-memory cache). Nodes index keyword hashes to encrypted IPFS CIDs and serve search results for ZK-gated decryption.
The Mathematics
Prouhet-Tarry-Escott (PTE)
The PTE problem asks: given two sets of integers, do they have equal power sums up to degree k? OnlyState uses this as a membership proof: a private vector V satisfies equal power sums against the group's public state.
Thue-Morse Sequence
The public group state is a Thue-Morse sequence — the same aperiodic binary sequence that underpins PIR. This creates a direct link between OnlyState and our PIR foundation.
Groth16 / snarkjs
The ZK proving system generates a 300-byte proof from the private vector. The proof demonstrates knowledge of a valid member vector without revealing which member. On-chain verification costs ~250k gas — fixed, regardless of group size.
BN254 Scalar Field
All ZK arithmetic happens in the BN254 prime field. No floats. Integers are scaled ×10⁶ for precision.
The OSTA Token
OSTA is minted exclusively by solving the ZK-PIR circuit and submitting a valid Groth16 proof on-chain. No staking. No time-based emissions. Only math.
Utility:
- Search fees → Coherence Nodes
- State creation burns
- Node staking
- DAO voting weight
- Compute bounties for ZK proof outsourcing
Implementation Status
- Demo playground — interactive React UI with Enclaves, Oracle, Miner, Attention Gate
- Circom ZK circuit — zk_pir.circom (N=16, C=4)
- Smart contracts — OSTA.sol + OnlyState.sol + Foundry tests
- Rust PIR Core — circuit.rs, proof.rs, verifier.rs
- Rust Coherence Node — axum + redb + moka indexer
- Browser WASM integration — snarkjs prover in demo
- Trusted setup ceremony — real MPC ceremony for mainnet
- Testnet deployment — Arbitrum Sepolia
- Cryptographic audit — ZK circuit audit (Veridise / Zellic)
Why It Matters
OnlyState demonstrates that PIR is not limited to AI governance. The same Thue-Morse equilibrium that detects market regime shifts and neural network instability can also serve as the foundation for cryptographic proofs of group membership.
This is PIR applied to blockchain: compressing infinite social graphs into a single integer, proving membership without revealing identity, and minting tokens through mathematics alone.
Published by Only Institute